Off-path hacking: The illusion of challenge-response authentication

Yossi Gilad, Amir Herzberg, Haya Shulman

Research output: Contribution to journalArticlepeer-review

Abstract

Everyone is concerned about Internet security, yet most traffic isn't cryptographically protected. The typical justification is that most attackers are off path and can't intercept traffic; hence, intuitively, challenge-response defenses should suffice to ensure authenticity. Often, the challenges reuse existing header fields to protect widely deployed protocols such as TCP and DNS. This practice might give an illusion of security. Recent off-path TCP injection and DNS poisoning attacks enable attackers to circumvent existing challenge-response defenses. Both TCP and DNS attacks are nontrivial, yet practical. The attacks foil widely deployed security mechanisms and allow a wide range of exploits, such as long-term caching of malicious objects and scripts.

Original languageEnglish
Article number6627890
Pages (from-to)68-77
Number of pages10
JournalIEEE Security and Privacy
Volume12
Issue number5
DOIs
StatePublished - Sep 2014

Keywords

  • DNS cache poisoning
  • TCP injections
  • challenge-response defenses
  • off-path attacks
  • security

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Electrical and Electronic Engineering
  • Law

Fingerprint

Dive into the research topics of 'Off-path hacking: The illusion of challenge-response authentication'. Together they form a unique fingerprint.

Cite this